v2.19
What's Changed
This update is expected to be backward-compatible.
- For RockyLinux 8, the updated kernel includes patches for CVE-2026-46333 (ssh-keysign-pwn), for which mitigations were provided in v2.17
- For RockyLinux 9, this will be the final RockyLinux 9.7 update before RockyLinux 9.8.
Security & Updates
- Update OS packages for RockyLinux 8.10 and 9.7 by @sjpb in #980. This provides kernels as follows:
- RL8: kernel-4.18.0-553.126.1.el8_10
- RL9: kernel-5.14.0-611.55.1.el9_7
General enhancements and fixes
- Fix image build post-filesystems hook by @sjpb in #970
- Use all ansible connection properties for dev/ansible-ssh by @sjpb in #977
StackHPC CI & development tools
- Use ephemeral keys for CI image build and refactor CI ssh configuration by @sjpb in #971
- Update node20 actions by @sjpb in #972
- Allow setting keypair name for stackhpc CI by @sjpb in #976
Full Changelog: v2.18...v2.19
Images
Two new images are available:
- RockyLinux 8: openhpc-RL8-260603-0842-b38bb57d
- RockyLinux 9: openhpc-RL9-260603-0842-b38bb57d